Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.146932
Category:Privilege escalation
Title:AnyDesk Desktop Privilege Escalation Vulnerability (Oct 2021) - Windows
Summary:AnyDesk Desktop is prone to a privilege escalation; vulnerability.
Description:Summary:
AnyDesk Desktop is prone to a privilege escalation
vulnerability.

Vulnerability Insight:
AnyDesk Desktop for Windows allows for a local escalation of
privileges through the UI. When a connection has been accepted, the user can click the 'Open Chat
Log' link in the connection window. This will open Notepad with escalated privileges. The user can
then use the 'File -> Open...' dialog, to start any application as administrator.

Vulnerability Impact:
A user with restricted privileges can use AnyDesk to obtain
administrator privileges.

Note: the vulnerability can not be exploited remotely because AnyDesk blocks remote interaction
with the chat window.

Affected Software/OS:
AnyDesk Desktop version 3.1.0 through 6.3.2 (excluding 6.2.6)
on Windows.

Solution:
Update to version 6.2.6, 6.3.3 or later.

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-40854
https://anydesk.com/cve/2021-40854/
CopyrightCopyright (C) 2021 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.